Improper control of interaction frequency in Moxa products - CVE-2019-6524

 

Improper control of interaction frequency in Moxa products - CVE-2019-6524

Published: February 26, 2019


Vulnerability identifier: #VU17866
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6524
CWE-ID: CWE-799
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform brute-force attack.

The vulnerability exists due to the application does not implement sufficient measures to prevent multiple failed authentication attempts, which makes the switches susceptible to brute force attacks.


Affected software

Moxa EDS-510A
Moxa EDS-408A
Moxa EDS-405A

How to mitigate CVE-2019-6524

Request updates from vendor's technical support.


External References

Related Security Bulletins